SMBs make up 70% of the 5,384 companies certified under EU-US Privacy Shield and face the biggest challenges in complying with the decision that struck it down
Emily Birnbaum / Protocol : Tweets: @accessnow and @tconnellyrte Tweets: @accessnow : A win for #privacy! 🎉 Today, in a landmark decision, the @EUCourtPress struck down the EU-US #PrivacyShield as it fails to protect people's rights to privacy, data protection and access to remedy. https://www.accessnow.org/... Tony Connelly / @tconnellyrte : 1/ The ECJ has struck down Privacy Shield because it essentially doesn't live up to the protections afforded to EU citizens by GDPR Furthermore, the ECJ says the scope of GDPR should reach all the way to the point at which US spy agencies start sifting through EU citizens data
Context & Ripple Effects
The Protocol piece quantifies who actually sits behind the EU-US Privacy Shield: of the 5,384 companies certified under the framework, roughly 70% are SMBs — meaning the population hit by the ECJ's strike-down, covered in our earlier reporting on the ruling against the transfer mechanism, skews heavily toward firms without in-house privacy counsel.
The arc matters here: the General Court agreed to hear the challenge back in mid-2019, giving certified companies over a year of runway that most small firms apparently didn't use, and EU watchdogs followed within days to warn there is no grace period once Schrems II lands. The eventual answer was a negotiated replacement — the 2023 deal later upheld by the General Court — but that relief came years too late for the smallest transferrers.
First-order effects
- Roughly 3,700 SMBs among the 5,384 certified companies lose their legal basis for EU-US data transfers overnight, while watchdogs' no-grace-period stance makes continued reliance on Privacy Shield certifications illegal rather than merely risky.
- Large multinationals flagged in the ruling's aftermath, such as Facebook, can redirect transfers through standard contractual clauses and dedicated compliance teams; the typical certified SMB has neither the lawyers nor the leverage to renegotiate contracts at that speed.
Second-order effects
- Compliance costs push small firms toward EU-hosted storage and processing alternatives, shifting spend from US SaaS vendors to providers that can keep personal data inside the bloc.
- US service providers serving European customers face pressure to absorb the burden themselves — offering EU-region hosting or contractual assurances — because their SMB customer base cannot self-comply under GDPR's requirement that protections extend all the way to where US spy agencies sift the data.
Third-order effects
- With judges having now thrown out two successive transatlantic pacts before upholding the third in court, cross-border data transfer frameworks are structurally litigation-prone, favoring companies that can survive multi-year legal cycles over the long tail of SMBs the frameworks nominally serve.
- If each invalidated mechanism triggers a years-long gap between ruling and replacement, the durable equilibrium is regionalized data infrastructure: firms design for data locality first and treat any US-EU transfer agreement as provisional rather than foundational.
The trend: Transatlantic data flows are settling into a judge-driven replace-and-challenge cycle in which each new pact buys legitimacy only until the next court test — and the compliance burden of that volatility falls hardest on the SMBs who dominate the certification rolls.